For businesses large and small, relying on a cloud-based collaboration and productivity suite such as Microsoft Office 365 is becoming the norm. Enhancing productivity in your organisation is vital to get ahead in 2017 - and using Office 365 can help, if it's used right...

Sober.c more toxic than first thought

McAfee upgrades status of bilingual worm

The McAfee Anti-Virus Emergency Response Team (Avert) has today increased its original low-risk threat assessment of the 'moderately prevalent' Sober.c worm to 'medium risk' status.

Sober.c contains its own SMTP engine and targets email addresses which it harvests from the victims' machines.

Once activated, it emails itself to the user's Microsoft Outlook address book with outgoing messages constructed using its SMTP engine. The messages may be written in either English or German, and the attachment filename can vary.

Users should immediately delete any email containing the following:

Subject:

Betr: Klassentreffen

Testen Sie ihren IQ

Bankverbindungs- Daten

Neuer Dialer Patch!

Ermittlungsverfahren wurde eingeleitet

Ihre IP wurde geloggt

Sie sind ein Raubkopierer

Sie tauschen illegal Dateien aus

Ich hasse dich

Ich zeige sie an!

Sie Drohen mir

you are an idiot

why me?

I hate you

Preliminary investigation were started

Your IP was logged

You use illegal File Sharing ...

Attachment:

www.iq4you-german-test.com

www.freewantiv.com

www.free4manga.com

www.free4share4you.com

www.tagespolitik-umfragen.com

www.onlinegamerspro-worm.com

www.freegames4you-gzone.com

www.boards4all-terror432.com

www.anime4allfree.com

www.animepage43252.com

yourmail

alledigis

aktenz

Attachments may end in any one of the following extensions and be preceded with .txt or .doc, and/or a random number:

com

bat

cmd

pif

scr

exe

After being executed, Sober.c extracts target email addresses from the victim's machine and writes them to the file SAVESYSS.DLL in the SysDir.

Two other copies of the worm are then dropped into SysDir, with varying filenames. For example, 'SysDir\ONDMONSTR.EXE' and 'SysDir\DATMSCRYPT.EXE'.

Avert warned in an advisory: "These two latter files are responsible for monitoring and maintaining that the worm stays resident in memory.

"Upon termination of one worm processes, another copy will restart the terminated process very quickly.

"Two processes run on the victim machine in order to ensure the worm stays memory resident."